helm-charts icon indicating copy to clipboard operation
helm-charts copied to clipboard

Set automountServiceAccountToken when service account is disabled

Open ZeynelKoca opened this issue 4 months ago • 2 comments

Proposal

When setting serviceAccount.created: false, the deployment still includes spec.template.spec.automountServiceAccountToken: true. Security scanning tools like ARMOsec see this as a security risk.

When serviceAccount.created: false, we should set spec.template.spec.automountServiceAccountToken: false

References

No response

ZeynelKoca avatar Aug 29 '25 09:08 ZeynelKoca

@ZeynelKoca Thanks for raising this. Can you please provide PR?

gitkent avatar Oct 02 '25 12:10 gitkent

Hello, I created a MR for this !69.

JulesdeCube avatar Oct 22 '25 13:10 JulesdeCube